CVE-2019-19352: High severity red hat openshift container platform vulnerability
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/presto-container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19352?
CVE-2019-19352 is an insecure modification vulnerability in the /etc/passwd file in the operator-framework/presto as shipped in Red Hat Openshift 4.
What is the severity of CVE-2019-19352?
CVE-2019-19352 has a severity rating of high.
How does CVE-2019-19352 affect Red Hat Openshift 4?
CVE-2019-19352 affects Red Hat Openshift 4 when using the operator-framework/presto version included in the platform.
How can an attacker exploit CVE-2019-19352?
An attacker with access to the container could exploit CVE-2019-19352 to modify the /etc/passwd file and escalate their privileges.
How can I mitigate CVE-2019-19352?
To mitigate CVE-2019-19352, it is recommended to update the operator-framework/presto version to a secure version provided by Red Hat.